CompTIA CySA+ (CS0-003)Security OperationsMedium
A security analyst is investigating a report of slow network performance and suspicious activity on a critical database server. A packet capture reveals an unusually high volume of TCP packets with the SYN flag set, all originating from a single internal IP address (192.168.1.20) and targeting the database server's open port 1433 (MS SQL Server). Many of these SYN packets are not followed by an ACK from the source, and the server is showing a high number of half-open connections. Which type of denial-of-service attack is most likely occurring?
- AHTTP Flood
- BICMP Flood
- CSYN Flood
- DUDP Flood
Show answer & explanationAnswer & explanation
Correct answer: C. SYN Flood
The scenario describes a high volume of TCP SYN packets from a single source to a target port, with many unacknowledged SYNs leading to half-open connections on the server. This is the textbook definition of a SYN flood, a DoS attack that exploits the TCP three-way handshake by exhausting server resources with incomplete connection requests.
Why the other options are wrong
- A. HTTP flood attacks operate at the application layer and involve sending a high volume of legitimate-looking HTTP requests, not primarily SYN packets at the transport layer.
- B. ICMP flood attacks use ICMP (e.g., ping) packets to overwhelm a target and also do not involve TCP connections.
- D. UDP flood attacks use UDP packets and do not involve the TCP three-way handshake, so they wouldn't manifest as half-open TCP connections.
SYN Flood
A SYN flood is a type of denial-of-service (DoS) attack in which an attacker rapidly initiates a connection to a server but never completes the TCP three-way handshake. This leaves the server with many 'half-open' connections, exhausting its resources and preventing legitimate users from connecting.
- Exploits the TCP three-way handshake.
- Sends many SYN packets but no final ACK.
- Causes server resources to be tied up with half-open connections.
Memory trick: DoS attacks stop services from serving people.